Skip to main content
Hisabe
Legal

Privacy policy

Effective 7 August 2026

This Privacy Policy explains how Propgic (“Hisabe”, “we”, “us” or “our”) collects, uses, discloses and safeguards information when you visit our website, create an account, or use the Hisabe ERP platform and related apps (together, the “Service”). By using the Service, you agree to the practices described here.

1. Who this policy applies to

Hisabe is a business-to-business product. We act in two distinct roles:

  • As a data fiduciary for account, billing and website information — the data we collect directly from you to provide and operate the Service.
  • As a data processor for the business records you and your team enter into Hisabe(customers, suppliers, products, invoices, payments, and similar operational data). Your organisation controls that data; we process it on your behalf under our Terms of Service.

Some people use Hisabe without being our customer. If a business that uses Hisabe invites you as a customer or supplier to view your own orders, invoices, statements and enquiries, that business — not Hisabe — decides what data to hold about you and why. We process it on their instructions. Direct requests about that data to the business you deal with; if you send them to us, we will pass them on.

2. Information we collect

Information you provide

  • Account details: name, email address, phone number, organisation name, role, and password credentials.
  • Business profile: GSTIN, billing address, branch details and tax preferences used to configure your workspace.
  • Operational data: the records you create in the product — customers, suppliers, products, stock, invoices, orders, payments and reports.
  • Files and recordings: photos, PDFs and voice notes you attach to records — for example a photo of a handwritten list, or a spoken description of what you need on a sales enquiry. These are stored with the record they belong to and are visible to the business you sent them to.
  • Support communications: messages, attachments and feedback you send us.

Information we collect automatically

  • Usage data: features used, pages viewed, actions taken, and timestamps.
  • Device & log data: IP address, browser type, device identifiers, operating system, and diagnostic logs.
  • Cookies & similar technologies: used to keep you signed in, remember preferences, and understand how the Service is used (see Section 5).

Information from payment providers

When you subscribe to a paid plan, our payment processor collects and handles your payment details. We do not store full card numbers; we receive only confirmation of payment and limited billing metadata.

3. Mobile apps, permissions and device access

Our Android and iOS apps ask for the following device permissions. Each one is optional, is requested only when you first use the feature that needs it, and can be withdrawn at any time in your device settings — the rest of the app keeps working without it.

  • Microphone: to record a voice note describing what you need on a sales enquiry. Recording starts only when you tap record, is limited to two minutes, and you hear it back and choose whether to attach it before anything is sent. Attached recordings are uploaded to our servers and stored with the enquiry. We do not record audio in the background or at any other time.
  • Camera: to photograph products and to attach photos to records, such as a picture of a list you want to enquire about.
  • Photo library: to attach images you have already taken. We access only the items you pick.
  • Notifications: to alert you about stock, invoices, payments, orders and enquiries. To deliver these we store a push token that identifies your app installation, and share it with our push provider (see Section 7). Turning notifications off in your device settings stops this.
  • Face ID, Touch ID or fingerprint: to unlock the app. The check is performed entirely by your device’s operating system. We never receive, see or store your biometric data — the app is told only whether the check succeeded.

The apps also store your session locally on the device so you stay signed in. Signing out clears it.

4. How we use information

  • To provide, operate, secure and maintain the Service.
  • To authenticate users and manage organisation access.
  • To process subscriptions, invoices and payments.
  • To provide customer support and respond to your requests.
  • To monitor performance, prevent fraud and abuse, and improve product quality.
  • To send service-related notices (security, billing, and material changes) and, where permitted, product updates you can opt out of.
  • To comply with legal, tax and regulatory obligations.

We do not sell your data, and we do not use your business transaction data to train third-party AI systems.

5. Legal bases for processing

We process personal data where it is necessary to perform our contract with you, to comply with a legal obligation, for our legitimate business interests (such as securing and improving the Service), or on the basis of your consent, as applicable under the Digital Personal Data Protection Act, 2023 and other laws that apply to you. Where we rely on consent, you may withdraw it at any time.

6. Cookies and tracking

We use strictly necessary cookies to run the Service (for example, to keep you signed in) and limited analytics cookies to understand usage. You can control or block cookies through your browser settings, though some features may not work without them.

7. How we share information

We share information only as described below:

  • Service providers (sub-processors): partners who act on our instructions under confidentiality obligations. Today these are:
    • Amazon Web Services — application hosting, database, and storage of uploaded files including photos, documents and voice notes. Hosted in the Asia Pacific (Mumbai) region.
    • Amazon Simple Email Service — delivery of transactional email such as invitations, password resets and notifications.
    • Google Firebase Cloud Messaging — delivery of push notifications to your device. It receives the push token and the notification content, not your business records.
    • Payment processor — subscription billing, as described in Section 2.
  • Within your organisation: data you enter is visible to authorised users in your workspace, according to the roles and permissions you configure.
  • Legal requirements: when required by law, regulation, court order, or to protect our rights, users or the public.
  • Business transfers: in connection with a merger, acquisition or sale of assets, subject to this policy.

8. Data storage and security

We host data with reputable cloud infrastructure providers and apply administrative, technical and physical safeguards — including encryption in transit, access controls, and tenant isolation — to protect information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

9. Data retention

We retain account and operational data for as long as your organisation maintains an active account, and thereafter only as needed to comply with legal, tax and accounting obligations or to resolve disputes. You can request export or deletion of your data as described below; some records may be retained where the law requires us to keep them.

Files you attach — photos, documents and voice notes — are kept for as long as the record they belong to. Deleting an enquiry or the account it sits under removes them on the same schedule as the rest of that organisation’s data.

10. Your rights

Subject to applicable law, you may have the right to access, correct, update or delete your personal data, to withdraw consent, to request a copy of your data, and to nominate another person to exercise your rights in case of death or incapacity. To exercise these rights, contact us at connect@oadbox.com. Where Hisabe processes data on behalf of your organisation, we will direct your request to that organisation.

11. Your responsibilities

If you use Hisabe to process personal data about your own customers or staff, you are responsible for having a lawful basis to collect and share that data with us, for honouring data-subject requests, and for configuring access within your workspace appropriately.

12. Children

The Service is intended for businesses and is not directed to individuals under 18. We do not knowingly collect personal data from children.

13. International transfers

Your account data, business records and uploaded files are stored and processed in India, in Amazon Web Services’ Asia Pacific (Mumbai) region. One exception: push notifications are delivered through Google Firebase Cloud Messaging, which may process the push token and notification content on infrastructure outside India. Where data is transferred to or accessed from another country, we take steps to ensure it remains protected in line with this policy and applicable law.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, notify you through the Service or by email. Continued use of the Service after changes take effect constitutes acceptance.

15. Contact & grievances

For questions about this policy or to raise a grievance about how we handle your data, contact our Grievance Officer: